NVIDIA
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any NVIDIA product.
RSS Feeds for NVIDIA security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in NVIDIA products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by NVIDIA Sorted by Most Security Vulnerabilities since 2018
Recent NVIDIA Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 5903 | Security Bulletin: NVIDIA Model-Optimizer - October 2026 | October 6, 2026 |
| 5891 | Security Bulletin: TensorRT - October 2026 | October 6, 2026 |
| 5861 | Security Bulletin: GPU Display Driver – September 2026 | September 30, 2026 |
| 5847 | Security Bulletin: NVIDIA Networking BlueField, ConnectX - September 2026 | September 29, 2026 |
| 5886 | Security Bulletin: NVIDIA DeepStream - September 2026 | September 29, 2026 |
| 5879 | Security Bulletin - NVIDIA Infrastructure Controller - August 2026 | September 22, 2026 |
| 5885 | Security Bulletin - NeMo Speech - August 2026 | September 22, 2026 |
| 5875 | Security Bulletin - Triton Inference Server - August 2026 | September 8, 2026 |
| 5868 | Security Bulletin: Megatron Bridge - September 2026 | September 1, 2026 |
| 5872 | Security Bulletin: NVIDIA NemoClaw and OpenShell - August 2026 | August 25, 2026 |
By the Year
In 2026 there have been 363 vulnerabilities in NVIDIA with an average score of 7.4 out of ten. Last year, in 2025 NVIDIA had 174 security vulnerabilities published. That is, 189 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.62.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 363 | 7.36 |
| 2025 | 174 | 6.74 |
| 2024 | 34 | 6.81 |
| 2023 | 28 | 6.22 |
| 2022 | 43 | 6.70 |
| 2021 | 75 | 6.54 |
| 2020 | 35 | 6.78 |
| 2019 | 16 | 6.90 |
| 2018 | 7 | 5.50 |
It may take a day or so for new NVIDIA vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent NVIDIA Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-65142 | Oct 06, 2026 |
NVIDIA Model-Optimizer: Untrusted Deserialization Causing RCENVIDIA Model-Optimizer contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-65122 | Oct 06, 2026 |
NVIDIA TensorRT OOB Read leading to DoSNVIDIA TensorRT contains a vulnerability where an attacker can cause an out of bounds read. A successful exploit of this vulnerability may lead to denial of service. |
|
| CVE-2026-47539 | Sep 30, 2026 |
NVIDIA vGPU KGPT numeric conversion flaw allows code execNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an incorrect numeric conversion. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47496 | Sep 30, 2026 |
NVIDIA vGPU: OOB Write via RPC Enables Privilege EscalationNVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC call to the host. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and denial of service. |
|
| CVE-2026-47574 | Sep 30, 2026 |
NVIDIA vGPU VM: Incorrect Resource Transfer VulnerabilityNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability where an attacker could cause incorrect resource transfer between spheres. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47544 | Sep 30, 2026 |
NVIDIA vGPU Manager Linux Kernel OOB Read VulnerabilityNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47541 | Sep 30, 2026 |
NVIDIA vGPU Manager Linux Kernel OOB Write Privilege EscalationNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47536 | Sep 30, 2026 |
NVIDIA vGPU vGPU Manager Kernel Mode OOB ReadNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47535 | Sep 30, 2026 |
NVIDIA vGPU VM Linux OOB Read in Firmware Possible Priv EscalationNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47521 | Sep 30, 2026 |
NVIDIA vGPU Manager Linux Kernel OOB Read VulnerabilityNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47520 | Sep 30, 2026 |
NVIDIA vGPU Virtual GPU Manager Linux Kernel OOB Read VulnerabilityNVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47519 | Sep 30, 2026 |
Out-of-Bounds Read in NVIDIA vGPU Virtual GPU Manager Kernel (CVE-2026-47519)NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47503 | Sep 30, 2026 |
NVIDIA vGPU Driver OOB Write in Linux VMNVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an out-of-bounds write by sending a crafted RPC message with invalid performance state list size parameters. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47499 | Sep 30, 2026 |
NVIDIA vGPU Manager OOB Read Enables PrivEsc & Code ExecNVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a guest could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47498 | Sep 30, 2026 |
NVIDIA vGPU Manager GSP Plugin OOB Write CVE-2026-47498NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47497 | Sep 30, 2026 |
NV Virtual GPU Manager GSP Tracing Buffer Escalation VulnerabilityNVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47495 | Sep 30, 2026 |
NVIDIA vGPU Virtual GPU Manager Kernel OOB Write PrivEscNVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47493 | Sep 30, 2026 |
NVIDIA vGPU GPU Kernel Driver Privileged Host Resource Access VulnerabilityNVIDIA vGPU software for Windows and Linux contains a vulnerability in the GPU kernel driver where a guest may access privileged host GPU resources for which it is not authorized. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. |
|
| CVE-2026-47562 | Sep 30, 2026 |
Kernel Log Injection in NVIDIA GPU Display Driver (Linux)NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log because the supplied version string is not properly sanitized. A successful exploit of this vulnerability might lead to denial of service and data tampering. |
And others... |
| CVE-2026-47531 | Sep 30, 2026 |
NVIDIA GPU Display Driver Null-Pointer Deref for DOSNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47526 | Sep 30, 2026 |
NVIDIA GPU Display Driver Null Pointer Deref in Firmware (DoS)NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause a null pointer dereference. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47604 | Sep 30, 2026 |
Local User Info Disclosure via Missing Auth in NVIDIA GPU Display DriverNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure. |
|
| CVE-2026-47603 | Sep 30, 2026 |
Information Disclosure: NVIDIA GPU Display Driver Cross-Process Channel ReadNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user may access another process's GPU channel state due to missing authorization checks. A successful exploit of this vulnerability might lead to information disclosure. |
And others... |
| CVE-2026-47584 | Sep 30, 2026 |
NVIDIA GPU Display Driver Windows Null Pointer DerefNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where an attacker with local access could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47581 | Sep 30, 2026 |
Kernel Locking Flaw in NVIDIA GPU Display Driver (Windows)NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel module where a user could cause improper locking. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47568 | Sep 30, 2026 |
Uncontrolled Kernel Log Generation in NVIDIA GPU Display Driver (Linux)NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause uncontrolled kernel log generation by repeatedly invoking an interface that emits unrate-limited error messages. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47567 | Sep 30, 2026 |
NVIDIA GPU Display Driver Kernel Mode Layer VMA Exhaustion Denial of ServiceNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a user could cause uncontrolled resource consumption by exhausting the DRM VMA offset address space. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47566 | Sep 30, 2026 |
Kernel Memory Leak in NVIDIA Linux GPU Driver: Denial of ServiceNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a memory leak in error paths leading to kernel memory exhaustion. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47557 | Sep 30, 2026 |
NULL Pointer Deref in NVIDIA Linux GPU Display Driver (CVE-2026-47557)NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47555 | Sep 30, 2026 |
NVIDIA GPU Display Driver: Uninitialized Kernel Memory Copy to User SpaceNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where a user could cause uninitialized kernel memory to be copied back to userspace. A successful exploit of this vulnerability might lead to information disclosure. |
And others... |
| CVE-2026-47549 | Sep 30, 2026 |
NVIDIA GPU Display Driver: Unprivileged Local NULL Deref DoSNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel module where an unprivileged local user could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47534 | Sep 30, 2026 |
NVIDIA GPU Display Driver Kernel Divide-by-Zero Denial of ServiceNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause a divide by zero. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47517 | Sep 30, 2026 |
Local Null-Pointer Dereference in NVIDIA Linux GPU Driver via ioctlNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by submitting a crafted ioctl. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47506 | Sep 30, 2026 |
NV GPU Display Driver Kernel Stack Overflow: YCbCr420 EmulationNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel-mode color transform path where excessive kernel stack use occurs when evaluating YCbCr420 display emulation. A successful exploit of this vulnerability might lead to denial of service. |
|
| CVE-2026-47492 | Sep 30, 2026 |
NVIDIA GPU Display Improper Access Control in Kernel Mode (CVE-2026-47492)NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an attacker can cause improper access control. A successful exploit of this vulnerability might lead to denial of service. |
And others... |
| CVE-2026-47518 | Sep 30, 2026 |
NVIDIA GPU Display Driver Privilege Escalation via Secure MCU Permission FlawNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a secure microcontroller component, where incorrect permission assignment for a critical resource allows an attacker with privileged local access to modify protected memory that should be restricted. A successful exploit of this vulnerability might lead to code execution and escalation of privileges. |
|
| CVE-2026-47586 | Sep 30, 2026 |
Use-After-Free in NVIDIA GPU Display Driver Kernel ModuleNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47565 | Sep 30, 2026 |
NVIDIA GPU Display Driver Linux Kernel Race Condition OOB WriteNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a privileged user could trigger a race condition that leads to an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47547 | Sep 30, 2026 |
NVIDIA GPU Display Driver Firmware Buffer Overflow Remote Code ExecNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47546 | Sep 30, 2026 |
NVIDIA GPU Display Driver Improper Input Validation (CVE202647546)NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47543 | Sep 30, 2026 |
VIDIA GPU Display Driver KMD Buffer Overflow Enables Privilege EscalationVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47542 | Sep 30, 2026 |
NVIDIA GPU Display Driver kernel mode validation flaw enables code execNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47538 | Sep 30, 2026 |
OOB Write in NVIDIA GPU Display Driver Enables Code ExecutionNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47537 | Sep 30, 2026 |
CVE-2026-47537: NVIDIA Linux GPU Driver OOB Write (Kernel Mode)NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47533 | Sep 30, 2026 |
NVIDIA GPU Driver Kernel Array Index Validation VulnerabilityNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47532 | Sep 30, 2026 |
NVIDIA GPU Display Driver OOB Write in Kernel Mode Layer (CVE-2026-47532)NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47529 | Sep 30, 2026 |
NVIDIA GPU Display Driver for Linux: Out-of-Bounds Write in Kernel Mode LayerNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47527 | Sep 30, 2026 |
NVIDIA GPU Display Driver OOB Read & Possible Code Exec via FirmwareNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47525 | Sep 30, 2026 |
NVIDIA GPU Display Driver Improper Array Index ValidationNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|
| CVE-2026-47524 | Sep 30, 2026 |
NVIDIA GPU Display Driver OOB Read in Kernel Mode (CVE-2026-47524)NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |
|